CVE-2026-13129
EUVD-2026-4218208.07.2026, 09:16
When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| foxit | pdf_editor | 𝑥 ≤ 13.2.4.24048 |
| foxit | pdf_editor | 14.0.0.33046 ≤ 𝑥 ≤ 14.0.4.33508 |
| foxit | pdf_editor | 2023.1.0.15510 ≤ 𝑥 ≤ 2023.3.0.23028 |
| foxit | pdf_editor | 2024.1.0.23997 ≤ 𝑥 ≤ 2024.4.1.27687 |
| foxit | pdf_editor | 2025.1.0.27937 ≤ 𝑥 ≤ 2025.3.0.35737 |
| foxit | pdf_editor | 2026.1.0.36452 ≤ 𝑥 ≤ 2026.1.1.36485 |
| foxit | pdf_reader | 𝑥 ≤ 2026.1.1.36485 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration